DocumentCode :
3700081
Title :
SIEM approach for a higher level of IT security in enterprise networks
Author :
Kai-Oliver Detken;Thomas Rix;Carsten Kleiner;Bastian Hellmann;Leonard Renners
Author_Institution :
DECOIT GmbH, Fahrenheitstraß
Volume :
1
fYear :
2015
Firstpage :
322
Lastpage :
327
Abstract :
The threat of cyber-attacks grows up, as one can see by several negative security-news from companies and private persons. [7] Especially small-and-medium-sized enterprises (SME) are in focus of external attackers because they have not implemented sufficient security strategies and components for their networks yet. Additionally, tablets, smartphones, and netbooks changed the requirements of IT security rapidly. Today, there are several security components (e.g. anti-virus-system, firewall, and intrusion detection system) available to protect enterprise networks; unfortunately, they work independently from each other - isolated. But many attacks can only be recognized if logs and events of different security components are combined and correlated with each other. This possibility is offered by a security information and event management (SIEM) system. But nowadays these systems are very complex and expensive in deployment and maintenance ([12]). The SIMU project, funded by the BMBF [6] and presented in this paper, offers several features of a SIEM system with better handling and more efficient use in the SME environment.
Keywords :
"Security","Metadata","Servers","Engines","Companies","Computer architecture","Correlation"
Publisher :
ieee
Conference_Titel :
Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), 2015 IEEE 8th International Conference on
Print_ISBN :
978-1-4673-8359-2
Type :
conf
DOI :
10.1109/IDAACS.2015.7340752
Filename :
7340752
Link To Document :
بازگشت